Some checks failed
Dev CI / Backend — Lint (push) Successful in 1m4s
Dev CI / Security gate (push) Failing after 1m36s
Dev CI / Backend — Unit Tests (push) Successful in 1m7s
Dev CI / Frontend — Lint & Type-check (push) Successful in 1m51s
Dev CI / Frontend — Unit Tests (push) Successful in 1m22s
Dev CI / Notify Failure (push) Has been skipped
46 lines
2.1 KiB
Python
46 lines
2.1 KiB
Python
"""Diagnostics must not leak scanner evidence or report missing audits as clean."""
|
|
import contextlib
|
|
import importlib.util
|
|
import io
|
|
import json
|
|
from pathlib import Path
|
|
import tempfile
|
|
import unittest
|
|
|
|
spec = importlib.util.spec_from_file_location(
|
|
'security_summary', Path(__file__).with_name('summarize-security.py'))
|
|
summary = importlib.util.module_from_spec(spec)
|
|
spec.loader.exec_module(summary)
|
|
|
|
|
|
class SecuritySummary(unittest.TestCase):
|
|
def test_real_findings_are_counted_without_printing_evidence(self):
|
|
with tempfile.TemporaryDirectory() as temp:
|
|
reports = Path(temp)
|
|
for project in ('root', 'backend', 'frontend', 'log-exporter'):
|
|
(reports / f'npm-audit-{project}.json').write_text(json.dumps({
|
|
'metadata': {'vulnerabilities': {'high': 2, 'critical': 1}}}))
|
|
(reports / 'source-security.json').write_text(json.dumps({'Results': [{
|
|
'Secrets': [{'Match': 'DO-NOT-PRINT', 'Code': 'PRIVATE-CODE'}],
|
|
'Misconfigurations': [{'Description': 'PRIVATE-DESCRIPTION'}]}]}))
|
|
output = io.StringIO()
|
|
with contextlib.redirect_stdout(output):
|
|
self.assertEqual(summary.summarize(reports), 0)
|
|
text = output.getvalue()
|
|
self.assertIn('2 high, 1 critical', text)
|
|
self.assertIn('1 secret findings, 1 infrastructure findings', text)
|
|
self.assertNotIn('DO-NOT-PRINT', text)
|
|
self.assertNotIn('PRIVATE-', text)
|
|
|
|
def test_missing_and_failed_audits_are_not_reported_as_clean(self):
|
|
with tempfile.TemporaryDirectory() as temp:
|
|
reports = Path(temp)
|
|
(reports / 'npm-audit-root.json').write_text('{invalid')
|
|
(reports / 'npm-audit-backend.json').write_text('{"error": {"code": "NETWORK"}}')
|
|
output = io.StringIO()
|
|
with contextlib.redirect_stdout(output):
|
|
self.assertEqual(summary.summarize(reports), 1)
|
|
self.assertIn('dependency audit unavailable', output.getvalue())
|
|
self.assertIn('Source audit unavailable', output.getvalue())
|
|
self.assertNotIn('0 high', output.getvalue())
|